fingerprintd/packaging/fingerprintd.post-install
Jorijn van der Graaf 823c710b15
All checks were successful
package / package (push) Successful in 1m22s
0.2.4: the trustlet comes from the active slot, unpinned, and a refusal says why
0.2.3's manifest pinned the sha256 of one Android build's focal64
(16.82.0, the build the dev phone runs). Fairphone re-signs the trustlet
every release, so that pin matched exactly one of the six builds seen,
and two of two field reports had no sensor: one user on 16.100.0 edited
the manifest by hand, another ended up with a file QTEE refuses.

The manifest now carries '-' instead of a hash and depends on
fp6-vendor-blobs 1-r3, which tries the active slot first and verifies the
image's structure; QTEE's signature check is the gate it always was (one
flipped byte -> ERROR_ELF_SIGNATURE_ERROR, measured 2026-09-03 and again
today).

post-install reassembles the trustlet right away, so 'apk add' no longer
needs a boot for it. post-upgrade re-derives it from the active slot,
which replaces a hand-placed or wrongly pinned file, and then restarts
the daemon -- a plain restart, so a daemon that exited on a refused
trustlet comes back up on the re-derived one.

loadFromBuffer failures name the loader's verdict. The field's first
report was a bare result=12; it now reads ERROR_ELF_SIGNATURE_ERROR with
what to do about it. Probed on the phone with this build: a one-byte
tampered image and 100000 random bytes both print it, the pristine image
loads, and the suites pass 8/8.
2026-09-11 13:04:35 +02:00

16 lines
840 B
Shell
Executable file

#!/bin/sh
# SPDX-License-Identifier: GPL-3.0-only
# SPDX-FileCopyrightText: Copyright (C) 2026 Catcrafts®
#
# The trustlet is not in this package: fp6-vendor-blobs reassembles it from
# the phone's own modem partition (packaging/20-focal64.manifest). On an
# image's first boot its unit does that before udev; on a phone that is
# already running, do it now, so a fresh 'apk add fingerprintd' does not wait
# for a boot to have a sensor. --if-device makes this a quiet no-op inside
# build/CI chroots; --refresh re-derives the file from the active slot even if
# one is present, and never removes a file it cannot replace.
#
# The daemon itself starts at the next boot: its unit, module load and
# tmpfiles arrive with the -systemd subpackage, after this script has run.
/usr/lib/fp6-vendor-blobs/extract --if-device --refresh || :
exit 0